Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-5331. PoCs published by Number 7.
AI-analyzed exploit summary The exploit demonstrates XSS and LFI vulnerabilities in asaancart v-0.9 via the smarty_ajax plugin. It includes proof-of-concept URLs for both XSS and LFI attacks, targeting specific endpoints like calc.php, chat.php, and index.php.
Description
Directory traversal vulnerability in asaanCart 0.9 allows remote attackers to include arbitrary local files via a .. (dot dot) in the page parameter to index.php.
Exploits (1)
The exploit demonstrates XSS and LFI vulnerabilities in asaancart v-0.9 via the smarty_ajax plugin. It includes proof-of-concept URLs for both XSS and LFI attacks, targeting specific endpoints like calc.php, chat.php, and index.php.